A fast-moving NFT exploit on September 25, 2026 initially looked like a mass drain connected to Magic Eden. Transactions appeared as zero-ETH marketplace sales, valuable collectibles were leaving wallets, and the same marketplace contract kept appearing on-chain.
The more accurate explanation is narrower but no less serious: the vulnerability was in Limit Break’s Payment Processor, an NFT trading protocol that powered Magic Eden’s former Ethereum marketplace. Wallets that had previously granted operator approval to the affected contracts could remain exposed even after the frontend stopped operating.
Security researcher 0xQuit said he moved 23,155 NFTs worth more than $5.7 million into a rescue wallet before malicious actors could take them. His intervention is a strong example of why experienced white-hat researchers have become an essential—if informal—emergency response layer for Web3.
Why the incident was first described as a Magic Eden exploit
To an NFT holder watching assets move without permission, the distinction between a marketplace and its underlying settlement contract is not obvious. The suspicious transfers were linked to Payment Processor, which had been used by Magic Eden’s former Ethereum marketplace. That is why early reports understandably described the event as a Magic Eden exploit.
However, the vulnerable component was maintained by Limit Break. Magic Eden subsequently acknowledged in an interim update that the incident involved Payment Processor V2. The important takeaway is that a marketplace’s website can close or move to a different system while approvals granted to its old smart contracts remain active on-chain.
Limit Break describes Payment Processor as an NFT exchange protocol for ERC-721-C and ERC-1155-C tokens that is also backward compatible with ordinary ERC-721 and ERC-1155 collections. Its public repository positions it as a royalty-focused alternative to protocols such as Seaport and Blur.
How the exploit put NFT wallets at risk
Revoke.cash’s incident analysis now identifies the failure more precisely. A flaw in Limit Break’s Payment Processor let an attacker act as a wallet that had already approved the protocol. By exploiting its trade execution, an attacker could take an approved wallet’s NFT through a zero-price offer, or make that wallet buy a worthless NFT with approved WETH or other tokens. The owner did not have to sign the malicious trade.
This is why simply cancelling a listing, disconnecting a wallet or invalidating an old order is insufficient. The NFT operator and token spending approvals remain on-chain until revoked. Payment Processor V2 cannot be paused or upgraded, according to Revoke.cash, so unused V2 approvals remain a live risk across deployments. The analysis says V3 was paused on most chains, with an ApeChain exception at the time of its update.
If terms such as wallet address, EVM network and smart-contract approval are unfamiliar, our beginner guide to crypto wallet and EVM addresses explains the foundations.
According to 0xQuit’s initial account, the first malicious activity took 10 Meebits, 50 Otherdeeds, 10 World of Women NFTs and 235 Desperate ApeWives. It warned that many more approved wallets might be reachable.
How 0xQuit stepped in before more hackers could
Once the pattern was identified, speed mattered. A public exploit does not remain exclusive for long: other attackers monitor transactions, reproduce profitable techniques and compete to drain whatever is still available.
0xQuit contacted Limit Break and helped identify the contracts that needed attention. Payment Processor V3 could be paused in some places, but the Ethereum V2 contract could not simply be switched off. The ApeChain deployment also presented an immediate problem. With exposed wallets still carrying approvals, waiting for every owner to notice the warning was not realistic.
His response was to use the vulnerable route defensively. Instead of allowing copycats to transfer the NFTs into attacker-controlled wallets, he moved the exposed assets first into a publicly identified rescue wallet:
0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33
He stated that the NFTs in that wallet were safe and would be returned after their owners were no longer exposed. The claim site is now live as described below. This was protective custody during an active incident, not an ordinary purchase or a claim of ownership.
How many NFTs were rescued and what was lost?
Early reports counted 3,832 NFTs moved to safety on Ethereum. The operation expanded: 0xQuit later reported 23,155 NFTs worth more than $5.7 million rescued across the wider response. Revoke.cash describes the effort as led by 0xQuit with other security researchers. The smaller and larger NFT figures reflect different stages and scopes, and the rescued assets should not be counted as theft by the original attacker.
The loss side is separate. Revoke.cash currently reports at least $2.8 million in NFTs and tokens stolen, with attacks observed on Ethereum, Polygon, Base, Arbitrum and ApeChain. That is a running incident estimate, not a final audited total. An official comprehensive postmortem and final reconciliation have not been published at the time of this update.
Why 0xQuit is a boon for the NFT industry
Calling 0xQuit a boon for the industry is not simply about the dollar value attached to the rescue. It is about the unusual combination of technical skill, judgment, speed and credibility required to act during a live exploit.
A researcher in this situation has to understand complex smart-contract behavior, recognize the vulnerable path from noisy on-chain data and make decisions before malicious copycats do. He must also coordinate with protocol teams, keep a transparent record of what was moved and accept the responsibility of temporarily holding other people’s assets.
In effect, 0xQuit front-ran the hackers. Front-running usually has a negative meaning in crypto, but here the priority advantage was used defensively: he reached at-risk NFTs before attackers could and moved them somewhere safer.
That intervention likely prevented a far larger loss. It also gave thousands of owners time to revoke approvals rather than forcing each of them to race an automated drainer. In an ecosystem where immutable contracts and persistent approvals can leave no central emergency button, a trusted white hat can become the closest thing to a first responder.
At the same time, the NFT industry should not depend on individual heroes. Protocols need narrowly scoped permissions, tested pause mechanisms, responsible upgrade plans and clear procedures for old approvals when a marketplace is retired. 0xQuit’s work demonstrates the value of skilled security researchers, but it also exposes how much infrastructure still needs to improve.
What happened to the WETH?
0xQuit reported approximately 660 WETH exposed or lost during the fast-moving response, worth around $1.7 million at the time. This was a different attack path from the NFT rescue: the flaw could force wallets with a token allowance to purchase worthless NFTs. The 660 WETH figure is his early assessment; the final chain-by-chain loss and rescue totals require a formal reconciliation. Revoke.cash’s broader estimate of at least $2.8 million stolen includes NFTs and approved tokens, so these numbers should not simply be added together.
Saving millions of dollars in NFTs did not erase losses that attackers had already caused. The incident also reached wallets on networks beyond Ethereum, which is why checking approvals chain by chain matters.
What affected NFT holders should do now
Anyone who previously used an interface integrating Limit Break’s Payment Processor should check approvals on every chain they used. Review both NFT operator approvals and token allowances, including WETH. Revoke.cash’s incident page identifies affected networks and offers a checker. Compare any contract address shown in a wallet with trusted incident sources before approving a transaction.
- Payment Processor V2 on Ethereum:
0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834. Magic Eden has also warned former users about V2 approvals on Polygon and Base. - Payment Processor V3 on ApeChain:
0x9a1D00000000fC540e2000560054812452eB5366.
Cancelling an old listing, disconnecting a wallet or increasing a marketplace nonce does not remove an approval. Revoke the permission on-chain. Revoking protects assets still in the wallet, including future token deposits, but it cannot undo theft that already occurred.
How to claim an NFT held in the rescue wallet
Update, September 26, 2026: 0xQuit announced from his own account that the NFTs Are Safu claim site is live for NFTs he was able to rescue. Check whether your NFT is listed for the wallet that originally held it, revoke the exploitable Payment Processor approval first, and follow the site’s claim instructions. He says an optional donation may be included in the claim transaction; it is not presented as a requirement.
0xQuit has also flagged current claim problems: some collections’ transfer validator rules may block a return until their collection owners adjust settings, and wallet simulation may show a warning because the claim uses an EIP-7702 delegated wallet. A separate follow-up said mainnet claims were still being enabled when he posted it. Check his latest updates if a claim is unavailable; do not bypass a wallet warning without understanding the transaction.
Use the exact site linked in 0xQuit’s announcement, verify the domain before connecting, and never provide a seed phrase or private key to a recovery page or direct message. The site returns assets held in the white-hat rescue wallet; it cannot recover NFTs or WETH already taken by attackers.
The lasting lesson for NFT marketplaces and collectors
The most important lesson is that permissions live on-chain, not inside a marketplace’s website. Closing a tab, removing a listing or even shutting down a frontend does not automatically cancel what a user previously authorised a smart contract to do.
For collectors, approval hygiene should be routine: review permissions periodically, revoke contracts that are no longer used and separate valuable long-term holdings from wallets used for trading. For marketplaces and protocol developers, legacy contracts require active deprecation plans and prominent warnings—not quiet abandonment.
0xQuit’s rescue shows the best side of crypto security: a technically capable researcher seeing an unfolding disaster and choosing to protect strangers rather than profit from them. Moving 23,155 NFTs into safety did more than preserve an estimated $5.7 million in assets. It bought the ecosystem time—and showed why credible white-hat researchers are public infrastructure for an industry that too often discovers its weakest links in real time.